Related Vulnerabilities: CVE-2022-29810  

The Hashicorp go-getter library before 1.5.11 could write SSH credentials into its logfile, exposing sensitive credentials to local users able to read the logfile.

Description

The MITRE CVE dictionary describes this issue as:

The Hashicorp go-getter library before 1.5.11 could write SSH credentials into its logfile, exposing sensitive credentials to local users able to read the logfile.

Additional Information

  • Bugzilla 2080279: CVE-2022-29810 go-getter: writes SSH credentials into logfile, exposing sensitive credentials to local uses
  • CWE-532: Insertion of Sensitive Information into Log File
  • FAQ: Frequently asked questions about CVE-2022-29810